Clear rules for data, security, and working together
This page describes the website and free audit flow as they operate today. Project-specific security, confidentiality, data processing, scope, and service levels are agreed in writing before development.
Last updated: 30 July 2026
Provider identity pending confirmation
Agentary AI is a trading name operated from Romania. The operator’s exact legal name, registered office, Trade Register number, and tax identification number are being confirmed and must be added here before a paid engagement is concluded. Contact: [email protected].
Privacy notice
For website enquiries, the Agentary AI operator is the data controller. We collect the name, company, business email, automation description, request timestamps, limited security metadata, AI-assisted qualification output, and later correspondence.
We use this information to answer and assess pre-contractual requests, protect the service, keep necessary business records, and—where applicable—comply with legal obligations. We do not use the audit form for advertising lists and do not make decisions with legal or similarly significant effects solely by automated means.
- Legal bases: steps requested before a possible contract; legitimate interests in answering requests and securing the service; legal obligations where applicable; consent only where we separately ask for it.
- Retention: lead records for up to 180 days; anti-abuse records for up to 24 hours; business correspondence for up to 24 months unless a contract or law requires longer; accounting and contractual records for the statutory period.
- Language preference is stored locally in your browser. We currently use no advertising or behavioural analytics cookies. Cloudflare Turnstile may process security data when enabled.
- Data may be processed outside the EEA by listed providers using the safeguards offered by those providers and any required contractual protections.
- Do not submit special-category, criminal-offence, authentication, payment-card, or other unnecessary sensitive data in the free-text field.
Website and audit terms
- The website provides general information. Interactive demos, fictional organisations, and modelled metrics are illustrative and are labelled as such; they are not customer evidence or guaranteed outcomes.
- Submitting the form requests an initial fit review. It does not create a client relationship, promise acceptance, reserve capacity, or guarantee a particular deliverable or timeline.
- If discovery is appropriate, a written proposal will define the specific deliverables, integrations, assumptions, responsibilities, security measures, price, taxes, estimate, timeline, support, intellectual property, and acceptance criteria for that automation.
- Website prices and ROI calculations are indicative and may exclude VAT or third-party costs. Only a signed proposal or contract is binding.
- You must only provide information you are authorised to share. Do not probe, disrupt, scrape abusively, bypass access controls, or misuse the website or its endpoints.
- Mandatory Romanian and EU law remains unaffected. Unless mandatory law requires otherwise, Romanian law governs and competent Romanian courts resolve disputes.
Security overview
The public website is statically generated. The lead service is separated from the public files and uses server-side validation, rate limiting, protected human-review links, no-store responses, least-privilege file permissions, and short-lived appointment access. AI qualification is advisory and a person must approve a lead before an invitation is sent.
- TLS is required and security headers restrict framing, content types, referrers, browser permissions, and executable content.
- Secrets are stored outside the public web root. They are not embedded in the static website or returned to visitors.
- Lead records are access-controlled and automatically eligible for deletion after the stated retention period. Backups containing personal data or secrets are kept private.
- Responsible disclosure: send a concise report to [email protected]. Do not access other people’s data, disrupt service, or publicly disclose a vulnerability before remediation.
- No system is risk-free. Project controls depend on the client’s systems and are documented in the project proposal and, where required, an NDA or data-processing agreement.
Service providers
The website flow currently relies on the following categories of provider. This list is updated when the flow changes.
- HostX / cPanel — website, email, and file storage in our hosting environment.
- Google Gemini API — AI-assisted request qualification. Requests use store:false; public EEA use requires an eligible paid Gemini API project.
- Telegram — minimized internal review alert; the lead’s full message is not included in the alert.
- Cloudflare — DNS, TLS, CDN, bot protection, and security logging when proxying is enabled.
Your data rights
Depending on the circumstances, you may ask for access, correction, erasure, restriction, portability, or objection, and may withdraw consent where consent is the basis. Email [email protected]. We may request proportionate identity verification and normally respond within one month.
You may also complain to Romania’s National Supervisory Authority for Personal Data Processing (ANSPDCP) or the competent authority where you live or work.